Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Sign up or Login to participate.
|
|||||||
Begin your free trial now
Pay-as-you-go options starting at $10/user/month
Pay-as-you-go options starting at $10/user/month
Sagispul attack and maybe others
|
|
Thread Tools | Search this Thread |
|
#1
|
|||
|
|||
|
Sagispul attack and maybe others
Hi, I'm brand new to the forum. From what I've read, I'm glad to have found this site.
I started to get pop-ups to sagispul (sp?) plus my laptop was slow to boot and sometime had trouble rebooting. I followed the 8 step viruses/spyware/malware removal. I'm attaching my logs here. My laptop seems to be fine now, but any confirmation that I was successful or other steps I need to do would be greatly appreciated. Thanks! |
|
#2
|
|||
|
|||
|
Due to the huge amount of problems noted in HJT
I think you would be best to backup any data, and re-install Windows clean But this time don't install Symantec (Norton, that's presently running) or McAfee (running too) If you want to try repairing it, I'll be brief Uninstall your McAfee Then run the removal tool: http://download.mcafee.com/products/...tches/MCPR.exe Run the Norton Removal tool: ftp://ftp.symantec.com/public/englis...moval_Tool.exe Run Startup Control Panel and remove any not required startups: (should be most!) http://www.mlin.net/StartupCPL.shtml Install Avira Start up Malwarebytes again; Update it; then run a full scan (remove all found Malwares) There you go
|
|
#3
|
|||
|
|||
|
More info please...
Hi Kimsland, thank for you responding. Could you please elaborate on the huge amount of problems noted in HJT? I'm looking for examples so I can better understand what issues HJT shows. Thank you so much for your help.
|
|
#4
|
|||
|
|||
|
Code:
Memory Modules Infected: C:\WINDOWS\system32\nnnMDsqR.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\system32\tkrago.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\wvUMFYop.dll (Trojan.Vundo) -> Delete on reboot. This time, run both MBAM & SAS until clean or until it finds something that cannot be cleaned. Look for the 'reboot' & respond if found. Restart the computer immediately before running the HJT scan. This reflects the results of all the cleaning. Post new logs. |
|
#5
|
|||
|
|||
|
Restart
Yes, I did restart both after MBAM and SAS. I don't see any of the 3 files you noted in my windows/system32 folder. Should I run MBAM and SAS again?
|
|
|
|
#6
|
|||
|
|||
|
At the cost of 3 hours of scan-time, yes, I would rescan & post to confirm that the infection was handled. Now that MBAB has been updated to put down 'sagipsul' (or what ever the correct spelling is), it takes about 5 days for the 'beautifiers' take care of the small stuff such as this:
Quote:
|
|
#7
|
|||
|
|||
|
Ran again....
I ran MBAM and SAS again, as well as HijackThis. The logs for MBAB and SAS seem to indicate that the trojan/virus has been eliminated. The HJT log still shows the reference to the tkrago.dll. I'm attaching the logs. Thanks.
|
|
#8
|
|||
|
|||
|
Logs confirm the infection was handled.
Use 'regedit' to remove references to tkrago.dll Delete temp directory C:\Documents and Settings\John\Local Settings\Temp Rated questionable - O4 - HKCU\..\Run: [Download] "C:\Temp\SSGet.exe" 120 "" "" >> SSget O4 - HKLM\..\Run: [tgcmd] C:\Program Files\Support.com\bin\tgcmd.exe /server /startmonitor /deaf >> tgcmd Kimsland can weigh in on his assessment for problems with the HJT.
If clean, then Establish a new clean restore point and Clear your existing System Restore points:
|
![]() |
| Similar Topics | ||||
| Topic | Replies | Forum | ||
Sagispul Pop-up Issues
|
0 | Virus and Malware Removal | ||
sagispul pop ups
|
1 | Virus and Malware Removal | ||
Sagispul.com pop-up
|
5 | Virus and Malware Removal | ||
Sagispul and vundo
|
5 | Virus and Malware Removal | ||
Sagispul.com has got me
|
0 | Virus and Malware Removal | ||
| Thread Tools | Search this Thread |
|
|
All times are GMT -4. The time now is 11:34 AM.



Sagispul Pop-up Issues